Skip to content

Release notes for the September, 20 2026 update

Update Version 4.1.202609191521

New Features

Added Support for Zero Trust AWS CLI Sessions

Added Just-in-Time (JIT), Zero Trust access option to AWS management through the AWS Command Line Interface (CLI). This release introduces a new Asset Type — AWS — enabling brokered AWS CLI sessions with credential injection and full session auditing.

Capabilities include:

  • Shared credentials for accessing the AWS tenant, brokered from the Credential Vault
  • Credential injection into AWS CLI traffic, so credentials are never disclosed to the user or client device
  • Role-based access control (RBAC) for AWS CLI sessions and to in-session activities such as download and upload files
  • Interactive multi-level approval or automatic approval workflows for access requests
  • Session auditing and on-demand termination
  • Full session transcripts generated for post-session analysis
  • Session event logging for each executed command
  • Session Intelligence, delivering real-time notifications or automatic session termination based on anomalous user activity

Added Site-Level Subscription Reporting for Site Administrators

Site administrators can now review and manage notification subscriptions for other users at the site level. This includes subscribing users to notifications, as well as updating or deleting their existing subscriptions.

Extensions

  • Added support to report PowerShell MS Graph commands executed in Zero Trust sessions as session events to enable reporting, notifications and session intelligence actions and analytics.

  • Renamed PowerShell MS Graph channel to GRAPH.

  • Added support for the StartTLS extension for secure connections to LDAP servers and Microsoft Domain Controllers.

  • Added the option to enforce transport protocol in LDAP integrations.

  • Added support for applying multiple transport protocols when verifying and trusting certificates in the tenant key store in addition to automatic protocol negotiation.

  • Added support for triggering asset tasks on unlock or access request approval, enabling automated provisioning of access or accounts on endpoints across various Zero Trust access scenarios.

  • Added Active Directory LDAP script to unlock MS Active Directory account.

  • Added the option to delete import entries.

  • Added an option to the Users Report to synchronize user metadata with the source user directory.

Security

Components Update

  • Updated server side run time framework to the latest version.

  • Updated application WEB framework to the latest version.

  • Updated application WEB container to the latest version.

  • Updated database access component to the latest version.

  • Updated terminal emulator to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated client side markdown toolkit to the latest version.

  • Updated Code Editor component to the latest version.

  • Updated Duo Security driver to the latest version.

  • Updated non-FIPS cryptography module to the latest version.

Build components update

  • Updated application build helper plugin to the latest version.

  • Updated bill of materials tracking component to the latest version.

Fixes

  • Fixed the issue with editing assets with secured required fields.

  • Fixed the issue with displaying background run type property in the Jobs report export.

  • Fixed the issue with the Auditor subscribing to asset level notifications.

  • Improved stability of backup and replication synchronization operations.

  • Added a troubleshooting system log warning for repeating database operations, to help monitor database access health.

  • Fixed the issue with the rudimentary warning messages during installation on Linux platforms.

  • Fixed the issue with the error message about detecting current framework version for 5-element versions during application update on the Windows platforms.